PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49106 CRM Perks CVE debrief

CVE-2026-49106 is a critical vulnerability in the Integration for Contact Form 7 and Constant Contact plugin, with a CVSS score of 9.8. The vulnerability allows unauthenticated PHP object injection and affects versions up to 1.1.6. The CVE was published on 2026-06-15T21:17:20.630Z and last modified on 2026-06-15T21:24:32.790Z.

Vendor
CRM Perks
Product
Integration for Contact Form 7 and Constant Contact
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Administrators and users of the Integration for Contact Form 7 and Constant Contact plugin should be aware of this vulnerability and take necessary actions to mitigate it.

Technical summary

The vulnerability is caused by an unauthenticated PHP object injection in the Integration for Contact Form 7 and Constant Contact plugin. This allows attackers to inject malicious PHP objects, potentially leading to arbitrary code execution.

Defensive priority

high

Recommended defensive actions

  • Update the plugin to a version that is not vulnerable.
  • Refer to resourceLinkAnnotations for mitigation or vendor references: ref-4.

Evidence notes

The CVE was generated based on information from the NVD and Patchstack.

Official resources

CVE-2026-49106 was published on 2026-06-15T21:17:20.630Z and last modified on 2026-06-15T21:24:32.790Z.